Privacy Policy
The short version. Blooming Baby stores the records you create about your family so the app can show them back to you. We do not sell your information, we do not share it with advertisers, and there is no ad network in the app. The pattern summaries the app generates are produced on your own device, not by sending your child’s records to an outside AI service. You can export or permanently delete everything from inside the app at any time.
This policy explains what Blooming Baby (“we”, “us”) collects, why, where it is kept, and what control you have over it. It applies to the Blooming Baby mobile app and to bloomingbaby.app.
1. Who this policy is for
Blooming Baby is intended for use by parents, guardians and caregivers who are 18 years or older. The app is not directed to children and children may not create accounts.
The records you keep in the app describe a child, but the account, and the decision to record anything at all, belongs to you as the adult account holder. You are the one who chooses what to enter, and you can remove any of it at any time. We do not knowingly allow anyone under 18 to register.
2. What we collect
All of the following is information you choose to give us. We do not buy data about you from anyone else.
| Category | What it includes | Why we hold it |
|---|---|---|
| Account | Email address and a securely hashed password. If you sign in with Google, we receive your email address and basic profile information from Google — never your Google password. | To create your account, sign you in, and let you recover access. |
| Your profile | Your name, and optionally a phone number and a general location such as a city or neighbourhood. We never ask for a street address or precise GPS location. | To personalise the app and, where relevant, keep guidance regionally appropriate. The phone number is optional and is never used for marketing. |
| Child profile | The name or nickname you give, date of birth, and sex if you provide it. | To calculate age and organise records for the right child. |
| Family & sharing | The name you give a family, who is in it and what each person may do. If you invite someone, the email address you type for them — and nothing else about them. | So the other grown-ups caring for your child can see and add to the same record. An invited address is kept while the invitation is live (7 days) and for up to 30 days after it is used, cancelled or expires, then deleted. See section 5 for exactly what an invited person can and cannot see. |
| Care records | Feeds, sleep, diaper changes, foods and allergen introductions, growth measurements, medications, milestones, and any free-text notes you write. | These are the app’s core purpose — to keep your record and show it back to you. |
| Sick-day records | Symptoms you tick, an optional temperature and where you measured it, how rough you think things seem, and any notes you add. | To keep a record you can show your pediatrician, and to show you published guidance on when they ask to be called. The app never names a condition or tells you whether your child is ill. |
| Your own check-ins | Mood and self-care entries you optionally record for yourself, plus any measurements or medications you log for yourself. | To show you your own history over time. This is optional and can be left empty. |
| Photos | Images you attach to milestones or diaper entries. | To display them in your timeline. Stored privately, never in a public location. |
| Subscription status | Whether your account is on the free or paid tier, and when the current period ends. | To unlock paid features. We never see or store your card number. |
| App settings | Reminder preferences, streak and badge progress, and which onboarding steps you finished. | To make the app behave the way you set it up. |
| Waitlist (website only) | Your email address, the page you signed up from, and the site that referred you. | To confirm you’re on the list, to email you once when the app launches, and to send a short receipt if you unsubscribe. |
Some of this is health information — your child’s symptoms, temperature, growth and medication records, and your own mood check-ins. We treat it as the most sensitive data in the app. We use it only to show it back to you, and it is never used for advertising or shared with anyone beyond the providers listed in section 5.
The basis for holding it is your consent, which you give explicitly. The Philippine Data Privacy Act treats health information about a child as sensitive personal information, and GDPR treats it as a special category, so we do not infer your agreement from the fact that you started using the app. Before you add your first child, Blooming Baby asks you to tick a box confirming that you are the child’s parent or legal guardian and that you agree to us recording their health information. We record that you agreed, when, and which version of this policy you were shown. Agreeing to product emails is a separate, optional tick that you can decline without affecting anything else.
If we ever change what we collect or why, we will ask you again rather than assume the old agreement still covers it. You can see what you agreed to at any time in Settings → Data & consent, change the optional consent there, and withdraw your consent entirely by deleting your account — which erases the records it covered.
What we deliberately do not collect
- Precise or background location.
- Your contacts, calendar, call history or messages.
- Advertising identifiers, or any cross-app or cross-site tracking data.
- Card, bank or payment details — these go directly to Apple or Google and never reach us.
3. How the app’s insights work
Blooming Baby can summarise patterns in your logs — for example how feeds or naps have trended over recent days. This runs as a model on your own device. Your child’s records are not transmitted to an external AI provider in order to generate these summaries, and the summaries are not used to train anyone’s model.
If you choose to download an optional on-device language model, the download is fetched from a model host. That request tells the host that a download happened; it does not contain any of your family’s data.
Speaking a log entry. You can dictate a note instead of typing it. The app asks your phone to transcribe your speech on the device itself, so the audio does not leave it. Some phones cannot do this locally. When that happens we do not quietly fall back — we tell you, and dictation only proceeds if you agree, at which point your speech is sent to Apple or Google to be turned into text under their terms, exactly as the microphone key on your keyboard already does. You can decline and type instead, and you can change your mind at any time in Settings → AI Model. We never record or store audio; only the text you end up with is saved, and you can edit it before it is.
Reading a milestone aloud. A milestone can be read back to you with your phone’s own text-to-speech voice. The app asks for a voice that works without a connection, so what it reads — the milestone, its date and your note — stays on the device. If your phone offers only a voice that synthesises on a server, we do not use it: the button says so and nothing is read, rather than sending a note about your child away to be spoken.
Suggesting a name for a milestone. If you have downloaded the optional on-device model, it can propose a short title from the note you wrote. That runs on your phone, the note is not transmitted anywhere, and the suggestion is only ever offered — nothing is filled in or saved until you tap it.
4. Where your information is stored
We use Supabase as our hosting provider for our database, account system and file storage. Data is currently stored on Supabase infrastructure in the Asia–Pacific (Mumbai, India) region. If you use the app from another country, your information will be transferred to and stored there.
Every record is protected by row-level security rules enforced by the database itself, which restrict each row to the account that owns it. Photos are stored in private buckets and are served only through short-lived signed links to the account that uploaded them.
Your child’s records live only there. The one exception to “Mumbai” is the optional usage analytics described in section 9, which are processed in the United States — and which never contain your child’s records.
5. Who we share it with
We do not sell your personal information, and we do not share it for advertising or marketing purposes.
People you invite into your family
The app lets you share a child’s record with other grown-ups — the other parent, a grandparent, a nanny. This only ever happens because you invite them by email from Settings → Family & sharing. We never add anyone on our own, and nobody can add themselves.
- Everyone you invite into a family can see everything recorded for the children in that family: feeds, sleep, nappies, foods, milestones and their photos, growth measurements, medicines, and sick-day checks. Choose who you invite with that in mind.
- Your own personal entries are never shared. Your mood check-ins, your own weight and medicines, your streaks and badges, your reminders and your subscription stay yours alone, even from the people in your family. A family shares a child’s record, not yours.
- You choose what each person can do. A co-parent can add, change and remove records. A caregiver can see everything and log anything, but can only remove entries they made themselves, and cannot add or remove a child.
- You can remove someone at any time, and their access ends immediately — not at their next sign-in. Anything they logged stays in the child’s record; removing a person does not delete their entries.
- When you invite someone, we send one email to the address you enter, containing your first name, the family’s name and a code. It never contains your child’s name or any of their records. That address is stored while the invitation is live (7 days) and for up to 30 days after it is used, cancelled or expires, then deleted automatically. It is used for nothing else, and it is never added to any mailing list. Cancelling an invitation stops the code working immediately; the record is kept for that same short period so that someone typing an old code is told it was cancelled or has expired, rather than that they typed it wrong.
Beyond that, we share information only with the service providers who make the app run, and only to the extent they need it:
| Provider | Purpose | What they receive |
|---|---|---|
| Supabase | Database, authentication and file hosting | All account and record data described above |
| Sign-in with Google, if you choose it | Confirms your identity to us; we receive email and basic profile | |
| Apple / Google Play | App distribution and subscription billing | Payment details, handled entirely by them — we receive only whether a subscription is active |
| Cloudflare | Hosting for this website | Standard web request data such as IP address, for security and delivery |
| Mailjet | Sending the waitlist emails; family invitations you send; and product-update emails only if you ticked the optional box in the app | An email address, and nothing else. For an invitation, also your first name and the family’s name so the person can tell it is really from you. Never your child’s name or records, and never the fact that you agreed to us keeping them |
| PostHog | Product analytics and crash reports, only if you ticked the optional box in the app — plus basic visitor statistics on this website | Which screens you open, which features you use, and error reports. Your account ID (a random identifier), never your name or email. Never your child’s records — no names, birthdays, feeds, sleep, diapers, symptoms or temperatures. Servers in the United States |
There are two separate routes to Mailjet, and neither one feeds the other. From the app: Mailjet receives your address only while your optional consent stands. Turn it off in Settings → Data & consent and we unsubscribe you there; delete your account and you are unsubscribed as part of that. If you never tick that box, nothing about your account reaches Mailjet. From this website: joining the waitlist sends your address to Mailjet so we can send you the confirmation and, later, the launch email — that is the whole purpose of the form. Every one of those emails carries an unsubscribe link; using it removes you from both the list and our own table, and sends one short receipt so you have it in writing that it worked. Nothing follows that. Signing up here does not create an account, and it never adds you to app-related email.
We may also disclose information where we are legally required to, or where it is necessary to protect someone’s safety. If our business is ever transferred to another owner, we will tell you before your information becomes subject to a different policy.
6. How long we keep it
- While your account is open: your records are kept so the app can show them to you.
- When you delete your account: your profile, your children’s records and your uploaded photos are immediately and permanently deleted from our live systems. Where encrypted backups exist, a copy may persist in them for up to 30 days before they roll over, after which the data is gone.
- Waitlist emails: deleted once the launch email has been sent, or sooner if you ask — and removed from Mailjet at the same time. Unsubscribing stops the emails immediately, bar one short receipt confirming it; we keep the record of the unsubscribe itself so that we cannot accidentally add you back.
7. Your rights and controls
You can do all of the following without contacting us:
- See and correct — every record in the app can be opened, edited or deleted individually.
- Export — produce a PDF summary of your records to keep or share with your pediatrician.
- Delete everything — Settings → Delete account permanently removes your account and all associated records. This cannot be undone.
- Change your mind about the optional permissions — Settings → Data & consent shows what you agreed to and when, and lets you switch product emails and usage analytics off (or back on) at any time. Switching analytics off takes effect immediately.
Blooming Baby is subject to the Philippine Data Privacy Act of 2012 (RA 10173). You have the rights it gives you — to be informed, to access, to correct, to erasure or blocking, to object, to data portability, and to damages — and you may complain to the National Privacy Commission (privacy.gov.ph).
Depending on where you live, you may also have rights under laws such as the GDPR (EU/UK), the CCPA/CPRA (California), or your local data protection legislation — including the right to access, correct, delete, restrict or object to our processing of your information, to receive it in a portable format, and to complain to your data protection authority. To exercise any of these, write to [email protected]. We will respond within 30 days and we will not charge you or treat you differently for asking.
8. Security
Traffic between the app and our servers is encrypted in transit using TLS, and data is encrypted at rest by our hosting provider. Passwords are hashed and are never stored or visible in readable form. Database-level access rules restrict every record to its owning account.
No system is perfectly secure. If a breach ever affects your personal information, we will notify you and the relevant authorities as required by law.
9. Cookies and analytics
This website does not use advertising cookies or third-party tracking pixels, and the app contains no advertising SDK. We do use a product-analytics tool, PostHog, to see which parts of the app people actually use and to find out when something crashes. This section says exactly what that means, because a previous version of this policy promised we would tell you before it started.
In the app — off unless you turn it on.
- Analytics is a separate, optional tick-box on the permission screen you saw when you first signed in: “Help improve the app with usage analytics.” It is not bundled with the permission to record your baby’s health information, and leaving it unticked changes nothing about how the app works for you.
- If you leave it off, the app does not start the analytics tool at all — there is nothing running in the background waiting to be switched on.
- If you turn it on, we record structural things only: which screens you open, that a feed or a nap was logged and whether you typed or dictated it, whether voice transcription stayed on your device, and error reports when something breaks.
- We never send what you record about your baby. Not their name, not their birthday, not a feed volume, a sleep time, a diaper, a symptom, a temperature, or anything you typed in a notes field. The app is built so that these cannot be attached to an analytics event even by mistake.
- You are identified only by your account ID, a random identifier. Your name and email address are never sent.
- There is no screen recording in the app.
- You can turn it back off at any time in Settings → Data & consent. It stops immediately, not at the next restart.
On this website.
- We count page views and clicks, and whether a waitlist sign-up succeeded. The email address you type is not sent to the analytics tool — it goes only where section 5 says it goes.
- We also record errors — if a page breaks, we receive the error message and the line of our own code that produced it, so we can fix it. An email address that somehow ends up inside one of those messages is removed before it is sent.
- No cookies are set for this. The tool keeps a temporary identifier in your browser’s session storage, which is erased when you close the tab, so you are not followed between visits or across other websites.
- There is no screen recording here either.
- Our internal admin tools track nothing about you — no usage analytics, no visitor counting, no screen recording. They report only their own technical errors to us, and an error report is stripped of email addresses and account IDs before it leaves our server, so it describes what our code did wrong and not whose record was on screen.
In both cases PostHog receives your IP address and basic device information (browser or device type, operating system, and rough location derived from the IP), as any web service does, and processes it on servers in the United States. This is a transfer outside the Philippines; we rely on your consent and on PostHog’s contractual data-protection commitments for it.
10. Changes to this policy
If we make a material change, we will update the date at the top of this page and notify you in the app or by email before the change takes effect. Continuing to use Blooming Baby after that point means you accept the updated policy.
11. Who we are, and how to contact us
Blooming Baby is operated by Nathaniel Bulawan, an individual (sole proprietor) and a citizen of the Republic of the Philippines. He is the personal information controller under the Philippine Data Privacy Act, the data controller under the GDPR and equivalent laws, and acts as the Data Protection Officer for Blooming Baby.
Privacy questions, data requests, and anything you would raise with the Data
Protection Officer: [email protected]
Anything else: [email protected]